Provisions of the EU Cyber Resilience Act governing vulnerability reporting have come into force, establishing strict timelines for manufacturers to disclose security issues.
The regulation requires manufacturers of products with digital elements to issue an early warning within 24 hours of becoming aware that a vulnerability is being actively exploited. More detailed follow-up information must be provided later.
Scope Extends to Cryptocurrency Wallets
The Cyber Resilience Act applies to connected hardware and software products sold into the European market. Commercial hardware wallets and wallet software fall within this broader definition of products with digital elements, subjecting them to the same security obligations as other digital products.
This classification means wallet manufacturers must comply with the vulnerability-reporting requirements alongside existing financial and data-protection regulations.
Impact on Security Operations
The 24-hour reporting window fundamentally changes how companies handle vulnerability incidents. Engineering teams may still be investigating how an exploit works when the reporting obligation begins, requiring rapid coordination between legal, security, and engineering teams to determine whether the disclosure threshold has been met.
The law treats open-source software differently from commercial products, providing an important carve-out for non-commercial open-source development.
Crypto Security as Operational Resilience
For cryptocurrency companies, the regulation reflects a broader shift: wallet security is increasingly being regulated as ordinary software security. Historically, the crypto industry has separated smart-contract risk, custody risk, and cybersecurity into distinct categories. European regulators are now treating these as overlapping components of the same operational-resilience problem.


